Hi all,
Hopefully someone can assist me here. We are using Splunk Light Version 6.2.3 but have discovered recently that Splunk seems to stop logging for a few days once a new month starts.
For example, here is an extract of two random months this year:
April 30th 2017 - 123,323 Events
May 1st 2017 - 388 Events
May 2nd 2017 - 0 Events
May 3rd 2017 - 0 Events
May 4th 2017 - 0 Events
May 5th 2017 - 287,234 Events
July 31st 2017 - 281,966 Events
August 1st 2017 - 426 Events
August 2nd 2017 - 0 Events
August 3rd 2017 - 0 Events
August 4th 2017 - 0 Events
August 5th 2017 -0 Events
August 6th 2017 - 0 Events
August 7th 2017 - 0 Events
August 8th 2017 - 327,876 Events
The same scenario has happened throughout the time we have been using Splunk, but we have only just spotted this today after looking at a yearly view.
Has anyone seen this issue before? Can anyone recommend a few troubleshooting tips?
Thanks in advance,
Jonathan
... View more